Command Execution Issue in Tenda AC6 Router by Tenda
CVE-2023-40839
9.8CRITICAL
What is CVE-2023-40839?
The Tenda AC6 router is affected by a command execution vulnerability present in the 'formSetIptv' function. This vulnerability arises from the improper handling of input parameters, specifically 'list' and 'vlanId'. These parameters are passed unfiltered into the 'sub_ADF3C' function, which allows attackers to execute arbitrary commands remotely. This represents a significant security risk, potentially compromising the integrity and security of affected devices.